CVE-2007-2850
Summary
| CVE | CVE-2007-2850 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-05-24 18:30:00 UTC |
| Updated | 2017-07-29 01:31:00 UTC |
| Description | The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address:port string. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Access Essentials | 1.0 | All | All | All |
| Application | Citrix | Access Essentials | 1.5 | All | All | All |
| Application | Citrix | Access Essentials | 1.0 | All | All | All |
| Application | Citrix | Access Essentials | 1.5 | All | All | All |
| Application | Citrix | Metaframe | 3.0 | All | microsoft_windows_2000 | All |
| Application | Citrix | Metaframe | 3.0 | All | microsoft_windows_2003 | All |
| Application | Citrix | Metaframe | 3.0 | All | x64_edition | All |
| Application | Citrix | Metaframe | 4.0 | All | microsoft_windows_2000 | All |
| Application | Citrix | Metaframe | 4.0 | All | microsoft_windows_2003 | All |
| Application | Citrix | Metaframe | 4.0 | All | x64_edition | All |
| Application | Citrix | Metaframe | 3.0 | All | microsoft_windows_2000 | All |
| Application | Citrix | Metaframe | 3.0 | All | microsoft_windows_2003 | All |
| Application | Citrix | Metaframe | 3.0 | All | x64_edition | All |
| Application | Citrix | Metaframe | 4.0 | All | microsoft_windows_2000 | All |
| Application | Citrix | Metaframe | 4.0 | All | microsoft_windows_2003 | All |
| Application | Citrix | Metaframe | 4.0 | All | x64_edition | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Citrix Products Session Reliability Service Security Bypass - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Vulnerability in Citrix Presentation Server's Session Reliability service could result in network security policy bypass | CONFIRM | support.citrix.com | |
| fortconsult.net/files/fortconsult.dk/citrix_advisory.pdf | MISC | fortconsult.net | |
| Citrix Presentation Server Session Reliability Flaw Lets Remote Users Bypass Security Policy Restrictions - SecurityTracker | SECTRACK | www.securitytracker.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.